CVE-2014-8761
published 2014-10-22CVE-2014-8761: inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.59%
73.0th percentile
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dokuwiki | < dokuwiki 0.0.20140505.a+dfsg-1 (bookworm) | dokuwiki 0.0.20140505.a+dfsg-1 (bookworm) |
| dokuwiki | dokuwiki | <= 2013-12-08 | — |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140505.a+dfsg-1 | 0.0.20140505.a+dfsg-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140505.a+dfsg-1 | 0.0.20140505.a+dfsg-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140505.a+dfsg-1 | 0.0.20140505.a+dfsg-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140505.a+dfsg-1 | 0.0.20140505.a+dfsg-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j352-5rrc-rrwv: inc/template
ghsa_unreviewed·2022-05-17
CVE-2014-8761 [MEDIUM] CWE-200 GHSA-j352-5rrc-rrwv: inc/template
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.
OSV
CVE-2014-8761: inc/template
osv·2014-10-22·CVSS 5.0
CVE-2014-8761 [MEDIUM] CVE-2014-8761: inc/template
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.
Debian
CVE-2014-8761: dokuwiki - inc/template.php in DokuWiki before 2014-05-05a only checks for access to the ro...
vendor_debian·2014·CVSS 5.0
CVE-2014-8761 [MEDIUM] CVE-2014-8761: dokuwiki - inc/template.php in DokuWiki before 2014-05-05a only checks for access to the ro...
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.
Scope: local
bookworm: resolved (fixed in 0.0.20140505.a+dfsg-1)
bullseye: resolved (fixed in 0.0.20140505.a+dfsg-1)
forky: resolved (fixed in 0.0.20140505.a+dfsg-1)
sid: resolved (fixed in 0.0.20140505.a+dfsg-1)
trixie: resolved (fixed in 0.0.20140505.a+dfsg-1)
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0438.htmlhttp://secunia.com/advisories/61983http://www.debian.org/security/2014/dsa-3059http://www.openwall.com/lists/oss-security/2014/10/13/3http://www.openwall.com/lists/oss-security/2014/10/16/9https://bugs.dokuwiki.org/index.php?do=details&task_id=2647#comment6204https://github.com/splitbrain/dokuwiki/issues/765http://advisories.mageia.org/MGASA-2014-0438.htmlhttp://secunia.com/advisories/61983http://www.debian.org/security/2014/dsa-3059http://www.openwall.com/lists/oss-security/2014/10/13/3http://www.openwall.com/lists/oss-security/2014/10/16/9https://bugs.dokuwiki.org/index.php?do=details&task_id=2647#comment6204https://github.com/splitbrain/dokuwiki/issues/765
2014-10-22
Published